Skip to content
Review Open access

Advanced Security through Hardware Capabilities: A Comprehensive Survey on CHERI Technology

Aug 2026 · ACM Computing Surveys · Vol 58, pp. 1 - 36 · 0 citations · 215 references

Abstract

As next-generation systems become increasingly complex and interconnected, they face the burden of new and numerous critical security challenges. Capability Hardware Enhanced RISC Instructions (CHERI) has emerged as a promising technology to mitigate memory safety vulnerabilities, one of the major security threats in current computing systems. CHERI introduces a hardware-enforced, fine-grained memory protection model that integrates a fat-pointer representation, combining memory bounds and permissions to ensure safer memory access and mitigate common memory-related exploits. Despite its potential, information about CHERI evolution, design principles, and applications is scattered among multiple sources, making it difficult to fully grasp and correlate its features and applications. This article aims to fill such gap by providing a detailed survey of CHERI technology, covering its historical evolution, key concepts, and current hardware and software implementations. We explore the ongoing challenges of its adoption in industry, the research efforts driving its growth as well as speculating and discussing future research directions.

Read PDF

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.